Home Newsletter Honored Guests Blog About Us Work With Us Sponsor & Advertise Be a Guest The Production Suite Get the Briefing
Cybersecurity

Is a Device With a USB Port a “Cyber Device” to the FDA?

By Open Door Salon · July 29, 2026
Is a Device With a USB Port a “Cyber Device” to the FDA?

Under the FDA's current thinking, a medical device is a cyber device if it has software and any means to connect to it, and that bar is far lower than most manufacturers assume. A single USB port, a Bluetooth radio, or an NFC chip is enough. On Open Door Salon, Christian Espinosa, founder and CEO of the medical-device cybersecurity firm Blue Goat Cyber, said companies keep trying to argue their device is out of scope, and the regulation keeps pulling it back in.

What actually makes a device a "cyber device"?

The definition turns on connectivity, not complexity. If there is software and any path to reach it, the device carries cybersecurity obligations, including the testing and controls that come with them.

"If your device has any kind of software and any means to connect to it, and this is what throws everybody off, any means at all, then it is a cyber device."

Espinosa said his firm sees a steady stream of companies asking for help arguing that their product is low-risk and not a cyber device. His answer is consistent: according to the regulation, if it has software and a way to connect, it is one.

Isn't a docker container or a plain USB port too simple to count?

This is the most common objection, and Espinosa hears it constantly. A team will insist the device just moves images through a docker container, or that a technician only occasionally pulls records off a USB port. Neither argument survives contact with the standard.

"Well, it's just this low-risk device that has a USB port we just periodically go and pull records off of. Well, that's an attack vector."

The mistake is thinking about the intended use instead of the misuse. A USB port meant for pulling logs is still a doorway, and the FDA evaluates the doorway, not the polite way you plan to use it.

Why does thinking in "misuse cases" change the answer?

Espinosa's team deliberately flips the frame. Instead of asking how the device is supposed to be used, they ask how it could be abused. That is where the real risk lives.

"You may only think I'm going to download the logs or patient images from the USB port, but we think what if we plug in a wireless adapter to the USB port. Now we can sit down the street and connect to that device and hack it all day."

A port designed for a five-second data pull becomes a permanent, remote entry point. The device's own convenience feature is the vulnerability, and no amount of describing the intended workflow removes it.

What are companies doing to dodge the requirement, and does it work?

Some manufacturers try to engineer their way out rather than comply. Edwin Lindsay, principal consultant and managing director at CS Lifesciences, described teams that had a device selling in the UK or EU with a USB port and, facing new FDA cybersecurity rules, simply looked for ways to disable the connectivity.

"They're looking at how do we not have to do it? How do we get to market… turning off the Bluetooth, removing the Bluetooth out of it."

The problem, Lindsay noted, is that stripping features to avoid testing often means the product no longer does what it was designed to do, and regulators in Europe are increasingly looking for the same controls anyway. Reinventing the product to avoid the rules rarely produces a product worth selling.

What is the takeaway for a medtech team?

Assume connectivity means scope. If a device has software and any way to reach it, plan for the full cybersecurity workload from the start rather than building a case that it is exempt. The teams that accept this early avoid the deficiency letters that catch the teams still arguing. How that software gets written matters too, which is where AI-assisted coding runs into the same regulatory wall. Where it gets built matters less than teams assume, which is why country of origin is a signal rather than a control. So does the money question, which is why reimbursement strategy belongs at the design stage rather than after clearance. This was one thread in a wider Open Door Salon conversation with Espinosa and Lindsay on the forces that make or break a medtech launch, drawn from the recorded, on-the-record discussion. Companies mapping their own attack surface can work with Open Door Salon to reach the decision-makers weighing these calls.

← Back to the Blog